blacklanternsecurity

71 mods across 2 repositories, 311 stars between them.

<skill-name>

25

blacklanternsecurity/red-run

Skill Claude CodeCodex

You are helping a penetration tester with . All testing is under explicit written authorization.

263 5mo ago A 40 tokens GPL-3.0

acl-abuse

26

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploits misconfigured Active Directory ACLs for privilege escalation. Covers GenericAll, GenericWrite, WriteDACL, WriteOwner, ForceChangePassword, targeted Kerberoasting via SPN manipulation, shadow credentials (msDS-KeyCredentialLink → PKINIT), and AdminSDHolder persistence.

263 5mo ago B 62 tokens GPL-3.0

ad-persistence

28

blacklanternsecurity/red-run

Skill Claude CodeCodex

Establishes persistent access in Active Directory environments after domain compromise. Covers DCShadow (rogue DC attribute modification), Skeleton Key (LSASS master password), custom SSP injection (credential logging via mimilib/memssp), security descriptor backdoors (WMI/WinRM/ DCOM/registry ACL modification), ADFS…

263 5mo ago A 106 tokens GPL-3.0

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploits ADCS through ACL abuse on templates/CA objects and NTLM relay to enrollment endpoints. Covers ESC4 (template ACL → modify to ESC1), ESC5 (PKI object ACLs), ESC7 (ManageCA/ManageCertificates abuse), ESC8 (NTLM relay to HTTP enrollment), ESC11 (NTLM relay to ICPR RPC).

263 5mo ago B 80 tokens GPL-3.0

adcs-persistence

30

blacklanternsecurity/red-run

Skill Claude CodeCodex

Establishes persistence and exploits weak certificate mapping in AD CS. Covers ESC9 (no security extension), ESC10 (weak certificate mapping), ESC12-15 (YubiHSM, issuance policy, altSecIdentities, application policies), Golden Certificate (forge with stolen CA key), certificate theft (DPAPI/CAPI/CNG), and account…

263 5mo ago A 80 tokens GPL-3.0

adcs-template-abuse

31

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploits misconfigured AD CS certificate templates to impersonate any domain user via SAN manipulation or enrollment agent abuse. Covers ESC1 (enrollee supplies subject), ESC2 (any-purpose/no EKU), ESC3 (enrollment agent), ESC6 (EDITFATTRIBUTESUBJECTALTNAME2 CA flag).

263 5mo ago A 69 tokens GPL-3.0

auth-coercion-relay

32

blacklanternsecurity/red-run

Skill Claude CodeCodex

Forces remote systems to authenticate back to attacker-controlled listeners and relays captured authentication to escalate privileges or move laterally. Covers authentication coercion (PetitPotam, PrinterBug, DFSCoerce, ShadowCoerce, CheeseOunce), NTLM relay (ntlmrelayx to LDAP/SMB/AD CS/MSSQL), Kerberos relay…

263 5mo ago B 105 tokens GPL-3.0

credential-dumping

33

blacklanternsecurity/red-run

Skill Claude CodeCodex

Extracts credentials from Active Directory: DCSync replication, NTDS.dit database extraction, SAM hive dump, Azure AD Connect (ADSync) credential extraction, LAPS passwords (legacy + Windows LAPS), gMSA passwords (KDS root key + GoldenGMSA), dMSA exploitation (BadSuccessor CVE-2025-21293), DSRM credentials, and…

263 5mo ago D 93 tokens GPL-3.0

gpo-abuse

34

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploits Group Policy Objects for code execution, privilege escalation, and lateral movement in Active Directory. Covers GPO enumeration (GPOHound, BloodHound, PowerView), exploitation via immediate tasks, logon scripts, and registry modifications (SharpGPOAbuse, PowerGPOAbuse, pyGPOAbuse, GroupPolicyBackdoor)…

263 5mo ago B 95 tokens GPL-3.0

kerberos-delegation

35

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploits Kerberos delegation misconfigurations for privilege escalation and lateral movement in Active Directory. Covers Unconstrained Delegation (TGT harvesting via coercion), Constrained Delegation (S4U2Self + S4U2Proxy with SPN swapping), and Resource-Based Constrained Delegation (RBCD via writable machine…

263 5mo ago B 75 tokens GPL-3.0

kerberos-roasting

36

blacklanternsecurity/red-run

Skill Claude CodeCodex

Extracts and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline password recovery.

263 5mo ago B 35 tokens GPL-3.0

blacklanternsecurity/red-run

Skill Claude CodeCodex

Forges Kerberos tickets for domain persistence and privilege escalation. Covers Golden Ticket (krbtgt hash → forged TGT), Silver Ticket (service hash → forged TGS), Diamond Ticket (decrypt/modify/re-encrypt legitimate TGT for stealth), Sapphire Ticket (U2U PAC swap), and Pass-the-Ticket injection.

263 5mo ago A 72 tokens GPL-3.0

pass-the-hash

38

blacklanternsecurity/red-run

Skill Claude CodeCodex

Authenticates to AD services using NTLM hashes, AES keys, or Kerberos tickets without cracking passwords. Covers Pass-the-Hash, Over-Pass-the-Hash, Pass-the-Key, and Pass-the-Ticket for lateral movement.

263 5mo ago B 52 tokens GPL-3.0

sccm-exploitation

39

blacklanternsecurity/red-run

Skill Claude CodeCodex

Enumerates and exploits Microsoft SCCM/MECM (System Center Configuration Manager / Microsoft Endpoint Configuration Manager) infrastructure for credential harvesting, lateral movement, and domain escalation. Covers SCCM enumeration (sccmhunter, SharpSCCM), Network Access Account (NAA) credential extraction (policy…

263 5mo ago D 129 tokens GPL-3.0

trust-attacks

40

blacklanternsecurity/red-run

Skill Claude CodeCodex

Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation. Covers trust enumeration (nltest, PowerView, BloodHound), SID history injection (child domain to forest root via golden/diamond ticket with extra SIDs), inter-realm TGT forging using trust keys…

263 5mo ago A 128 tokens GPL-3.0

password-spraying

41

blacklanternsecurity/red-run

Skill Claude CodeCodex

Performs password spraying against authentication services with lockout-safe techniques. Works against AD (SMB/Kerberos/LDAP), SSH, web login forms, OWA, and any service with username/password auth. Service-agnostic — the orchestrator passes target services and spray intensity tier.

263 5mo ago B 63 tokens GPL-3.0

red-run-ctf

42

blacklanternsecurity/red-run

Skill Claude CodeCodex

Multi-phase penetration test orchestrator. Handles recon, assessment surface mapping, vulnerability chaining, and routes to technique skills for execution. Invoke via /red-run-ctf slash command only.

263 5mo ago B 43 tokens GPL-3.0

av-edr-evasion

43

blacklanternsecurity/red-run

Skill Claude CodeCodex

Bypass antivirus and EDR detection for payload delivery during exploitation. Covers custom payload compilation (mingw C, Go), AMSI bypass, shellcode alternatives, and ETW patching. Route here when an agent reports a payload was quarantined, blocked, or detected by endpoint protection.

263 5mo ago B 64 tokens GPL-3.0

red-run-legacy

44

blacklanternsecurity/red-run

Skill Claude CodeCodex

Legacy subagent-based orchestrator. Superseded by /red-run-ctf (agent teams). Use /red-run-legacy to invoke manually. Does not auto-trigger.

263 5mo ago C 41 tokens GPL-3.0

blacklanternsecurity/red-run

Skill Claude CodeCodex

Database service enumeration and quick-win access checks for MSSQL, MySQL, PostgreSQL, Oracle, MongoDB, and Redis. Checks default/empty passwords, unauthenticated access, and command execution capabilities. Use after network-recon identifies database ports.

263 5mo ago A 56 tokens GPL-3.0

blacklanternsecurity/red-run

Skill Claude CodeCodex

Enumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection. Checks zone transfers, open relays, default community strings, cipher zero, NFS exports, and web technology fingerprinting. Use after network-recon identifies infrastructure ports.

263 5mo ago B 72 tokens GPL-3.0

network-recon

48

blacklanternsecurity/red-run

Skill Claude CodeCodex

Network reconnaissance, host discovery, port scanning, and OS fingerprinting. Produces a port/service map that the orchestrator uses to route to service-specific enumeration skills.

263 5mo ago B 37 tokens GPL-3.0